Microsoft Azure Sentinel: Planning and implementing Microsoft’s cloud-native SIEM solution (IT Best Practices – Microsoft Press)
$23.99
Price: $23.99
(as of Nov 23, 2023 17:57:00 UTC – Details)
Build next-generation security operations with Microsoft Sentinel
Microsoft Sentinel is the scalable, cloud-native, security information and event management (SIEM) solution for automating and streamlining threat identification and response across your enterprise. Now, three leading experts guide you step-by-step through planning, deployment, and operations, helping you use Microsoft Sentinel to escape the complexity and scalability challenges of traditional solutions. Fully updated for the latest enhancements, this edition introduces new use cases for investigation, hunting, automation, and orchestration across your enterprise and all your clouds. The authors clearly introduce each service, concisely explain all new concepts, and present proven best practices for maximizing Microsoft Sentinel’s value throughout security operations.
Three of Microsoft’s leading security operations experts show how to:
Review emerging challenges that make better cyberdefense an urgent prioritySee how Microsoft Sentinel responds by unifying alert detection, threat visibility, proactive hunting, and threat responseExplore components, architecture, design, and initial configurationIngest alerts and raw logs from all sources you need to monitorDefine and validate rules that prevent alert fatigueUse threat intelligence, machine learning, and automation to triage issues and focus on high-value tasksAdd context with User and Entity Behavior Analytics (UEBA) and WatchlistsHunt sophisticated new threats to disrupt cyber kill chains before you’re exploitedEnrich incident management and threat hunting with Jupyter notebooksUse Playbooks to automate more incident handling and investigation tasksCreate visualizations to spot trends, clarify relationships, and speed decisionsSimplify integration with point-and-click data connectors that provide normalization, detection rules, queries, and Workbooks
About This Book
For cybersecurity analysts, security administrators, threat hunters, support professionals, engineers, and other IT professionals concerned with security operationsFor both Microsoft Azure and non-Azure users at all levels of experience
From the Publisher
Who is this book for?
Microsoft Sentinel is for anyone interested in security operations in general: cybersecurity analysts, security administrators, threat hunters, support professionals, and engineers. It is designed to be useful for Azure and non-Azure users. You can have no security experience, some experience, or be a security expert, and you will get value from Microsoft Sentinel.
Microsoft Sentinel: Planning and implementing Microsoft’s cloud-native SIEM solution provides introductory, intermediate, and advanced coverage of a large swath of security issues that Microsoft Sentinel addresses.
In this book, you will learn:
How to connect different data sources to Microsoft SentinelHow to create security analyticsHow to investigate a security incident in Microsoft Sentinel
From the foreword
Microsoft Sentinel, formerly Azure Sentinel, was introduced in 2019 to help organizations modernize security operations in the cloud. At that time, security operations teams—who were under increasing pressure to extend coverage across a growing digital estate, combat escalating threats, and improve efficiency—were beginning to look to the cloud for alternatives to expensive and underperforming on-premises systems. Since then, tens of thousands of customers have adopted a cloud-first approach to power their data and compute-intensive security operations workloads, with Microsoft Sentinel becoming the solution of choice because of its cloud-native architecture and industry-leading intelligence and analytics capabilities. Today, some of the world’s largest Security Operations Centers (SOCs) run on Microsoft Sentinel, including Microsoft’s own SOC. As the hub for security operations, Microsoft Sentinel brings together data, analytics, and workflows to unify and accelerate threat detection and response across the customer’s entire digital estate. Microsoft Sentinel provides an extensible solution to power all facets of security operations (threat intelligence and hunting, detection and correlation, incident management, investigation, and remediation) and operate across all data sources.
In this second edition of Microsoft Sentinel: Planning and implementing Microsoft’s cloud-native SIEM solution, you will have the opportunity to learn from an expert team of cybersecurity experts and engineers who have helped countless customers and partners successfully transform their security operations. They will lay out the foundational aspects of architecting, implementing, and operationalizing Microsoft Sentinel for customers, large and small. Topics include data collection and archiving, threat hunting and detection, incident response and automation, threat intelligence, and more, with practical advice gained from real-world experience.
With the dynamic nature of the security landscape and rapid pace of innovation, this book provides the latest insights you need to realize the full potential of Microsoft Sentinel to help your SOC team achieve more.
Sarah Fender, Partner Director of Product Management, Microsoft Sentinel
Publisher : Microsoft Press; 2nd edition (August 19, 2022)
Language : English
Paperback : 240 pages
ISBN-10 : 0137900937
ISBN-13 : 978-0137900930
Item Weight : 16 ounces
Dimensions : 7.38 x 0.55 x 9.13 inches
User Reviews
Be the first to review “Microsoft Azure Sentinel: Planning and implementing Microsoft’s cloud-native SIEM solution (IT Best Practices – Microsoft Press)”
$23.99
There are no reviews yet.